[HN Gopher] The Claude Code Source Leak: fake tools, frustration...
___________________________________________________________________
The Claude Code Source Leak: fake tools, frustration regexes,
undercover mode
Related ongoing thread: _Claude Code 's source code has been leaked
via a map file in their NPM registry_ -
https://news.ycombinator.com/item?id=47584540 Also related:
https://www.ccleaks.com
Author : alex000kim
Score : 565 points
Date : 2026-03-31 13:04 UTC (9 hours ago)
(HTM) web link (alex000kim.com)
(TXT) w3m dump (alex000kim.com)
| pixl97 wrote:
| >Claude Code also uses Axios for HTTP.
|
| Interesting based on the other news that is out.
| alex000kim wrote:
| Oh right, I just saw
| https://news.ycombinator.com/item?id=47582220 will update the
| post with this link
| greenavocado wrote:
| What version?
| Stagnant wrote:
| 1.13.6, so should not be affected by the malware
| chuckadams wrote:
| The exploit is a postinstall hook, so CC users would be
| unaffected. Claude Code itself is most likely built with bun
| and not npm, so the CC developers would also be immune.
| username44 wrote:
| Just to corroborate sibling comments, I checked my Claude Code
| VM (native install) for the IOC and it does not appear
| infected.
| OfirMarom wrote:
| Undercover mode is the most concerning part here tbh.
| anonymoushn wrote:
| why
| AnimalMuppet wrote:
| Well, as a general rule, I don't do business with people who
| lie to me.
|
| You've got a business, and you sent me junk mail, but you
| made it look like some official government thing to get me to
| open it? I'm done, _just because you lied on the envelope_. I
| don 't care how badly I need your service. There's a dozen
| other places that can provide it; I'll pick one of them
| rather than you, because you've shown yourself to be
| dishonest right out of the gate.
|
| Same thing with an AI (or a business that creates an AI).
| You're willing to lie about who you are (or have your tool do
| so)? What else are you willing to lie to me about? I don't
| have time in my life for that. I'm out right here.
| simianwords wrote:
| What's the lie? It's just asking to not reveal internal
| names
| BoredPositron wrote:
| You are spamming the whole fucking thread with the same
| nonsense. It is instructed to hide that the PR was made
| via Claude Code. I don't know why people who are so AI
| forward like yourself have such a problem with telling
| people that they use AI for coding/writing, it's a
| weirdly insecure look.
| simianwords wrote:
| I can do that right now with Claude Code without this
| undercover mode.. In fact I do it many times at work.
| What's the big deal in this?
|
| Do you not think it is an overreaction to panic like this
| if I can do exactly what the undercover mode does by
| simply asking Claude?
| BoredPositron wrote:
| It's different if it's an institutional decision or a
| personal like in your case. Which is and I am repeating
| myself here borderline insecure.
| simianwords wrote:
| what's insecure about it? if it is up to the institution
| to make that decision - you can still do it. Claude is
| not stopping you from making that decision
| BoredPositron wrote:
| You have to work on your reading comprehension or you are
| intentional deceptive. Bye.
| simianwords wrote:
| ?? why doesn't your panic apply to other agents like
| Codex that don't advertise that the commit was made by an
| AI by default? strange!
| BoredPositron wrote:
| Because this thread is about claude. Are you that
| challenged?
| otterley wrote:
| Out of curiosity, given two code submissions that are
| completely identical--one written solely by a human and one
| assisted by AI--why should its provenance make any
| difference to you? Is it like fine art, where it's
| important that Picasso's hand drew it? Or is it like an
| instruction manual, where the author is unimportant?
|
| Similarly, would you consider it to be dishonest if my
| human colleague reviewed and made changes to my code, but I
| didn't explicitly credit them?
| AnimalMuppet wrote:
| Why does the provenance make any difference? Let me
| increase your options. Option 1: You completely hand-
| wrote it. Option 2: You were assisted by an AI, but you
| carefully reviewed it. Option 3: You were assisted by an
| AI (or the AI wrote the whole thing), and you just said,
| "looks good, YOLO".
|
| Even if the code is line-for-line identical, the
| difference is in how much trust I am willing to give the
| code. If I have to work in the neighborhood of that code,
| I need to know what degree of skepticism I should be
| viewing it with.
| otterley wrote:
| That's the thing. As someone evaluating pull requests,
| should you trust the code based on its provenance, or
| should you trust it based on its content? Automated
| testing can validate code, but it can't validate people.
|
| ISTM the most efficient and objective solution is to
| invest in AI more on both sides of the fence.
| AnimalMuppet wrote:
| In the future, that may be fine. We're not in that future
| yet. We're still at a place where I don't fully trust AI-
| only code to be as solid as code that is at least
| thoroughly reviewed by a knowledgeable human.
|
| (Yes, I put "AI-only" and "knowledgeable" in there as
| weasel words. But I think that with them, it is not
| currently a very controversial case.)
| feature20260213 wrote:
| Yes because you can be sued for copyright violation if
| you don't know the origin of one, and not the other.
| otterley wrote:
| As an attorney, I know copyright law. (This is not legal
| advice.) There's nothing about copyright law that says
| you have to credit an AI coding agent for contributing to
| your work. The person receiving the code has to perform
| their due diligence in any case to determine whether the
| author owns it or has permission from the owner to
| contribute it.
| hajile wrote:
| Can you back this up with legal precedence? To my
| knowledge, nothing of the sort has been ruled by the
| courts.
|
| Additionally, this raises another big issue. A few years
| ago, a couple guys used software (what you could argue
| was a primitive AI) to generated around 70 billion unique
| pieces of music which amounts to essentially every piece
| of copyrightable music using standard music scales.
|
| Is the fact that they used software to develop this
| copyrighted material relevant? If not, then their
| copyright should certainly be legal and every new song
| should pay them royalties.
|
| It seems that using a computer to generate results MUST
| be added as an additional bit of analysis when it comes
| to infringement cases and fair use if not a more
| fundamental acknowledgement that computer-generated
| content falls under a different category (I'd imagine the
| real argument would be over how much of the input was
| human vs how much was the system).
|
| Of course, this all sets aside the training of AI using
| copyrighted works. As it turns out, AI can regurgitate
| verbatim large sections of copyrighted works (up to 80%
| according to this study[0]) showing that they are in
| point of fact outright infringing on those copyrights. Do
| we blow up current AI to maintain the illusion of
| copyright or blow up current copyright law to preserve
| AI?
|
| [0] https://arxiv.org/pdf/2603.20957
| otterley wrote:
| You're asking a lot of very good and thoughtful
| questions, but none are directly related to the immediate
| issue, which is "do I have to credit the AI model?".
|
| To begin to answer your questions, I would suggest you
| study the Copyright Office's report (which is also not
| law, but their guidance for laypeople as written by their
| staff lawyers) at https://www.copyright.gov/ai/Copyright-
| and-Artificial-Intell...
| simianwords wrote:
| > The obvious concern, raised repeatedly in the HN thread: this
| means AI-authored commits and PRs from Anthropic employees in
| open source projects will have no indication that an AI wrote
| them. It's one thing to hide internal codenames. It's another to
| have the AI actively pretend to be human.
|
| I don't get it. What does this mean? I can use Claude code now
| without anyone knowing it is Claude code.
| slopinthebag wrote:
| I think it means OSS projects should start unilaterally banning
| submissions from people working for Anthropic.
| simianwords wrote:
| Why? What does this have to do with the leak
| alex000kim wrote:
| technically you're correct, but look at the prompt
| https://github.com/alex000kim/claude-code/blob/main/src/util...
|
| it's written to _actively_ avoid any signs of AI generated code
| when "in a PUBLIC/OPEN-SOURCE repository".
|
| Also, it's not about you. Undercover mode only activates for
| Anthropic employees (it's gated on USER_TYPE === 'ant', which
| is a build-time flag baked into internal builds).
| simianwords wrote:
| I don't know what you mean. It just informs to not use
| internal code names.
| giancarlostoro wrote:
| I agree with you, I think people are overthinking this.
| robflynn wrote:
| It also says don't announce that you are AI in any way
| including asking it to not say "Co-authored by Claude". I
| read the file myself.
|
| I'm still inclined to think people might be overreacting to
| that bit since it seems to be for anthropic-only to prevent
| leaking internal info.
|
| But I did read the prompt and it did say hide the fact that
| you are AI.
| simianwords wrote:
| Why does that matter though
| robflynn wrote:
| There are probably different reasons for different
| people. I can definitely see the angle that trying to
| specifically pretend to not be AI when contributing to
| open source could be seen as a bad thing due to the open
| source supply chain attacks, some AI-driven, that we've
| been having, not to mention the AI-slop PR spam.
|
| But, I also get Anthropic's side that when they're
| contributing they don't want their internals leaked. If
| it had been left at that, that's fine, but having it
| pretend like it's not AI at all rubs me a little bit the
| wrong way. Why try to hide it?
| simianwords wrote:
| >There are probably different reasons for different
| people. I can definitely see the angle that trying to
| specifically pretend to not be AI when contributing to
| open source could be seen as a bad thing due to the open
| source supply chain attacks, some AI-driven, that we've
| been having, not to mention the AI-slop PR spam.
|
| But none of the other agents advertise that the commit
| was done by an agent. Like Codex. Your panic should apply
| equally to already existing agents like Codex no?
| hrmtst93837 wrote:
| If anybody cares about AI-written code slipping in they can
| grep for style tells or run a classifier against a suspect
| repo. You won't get guarantees. Watermarks and disclosure tags
| die the moment someone edits the patch, so secret strings and
| etiquette signs are cargo cult security and the only answer is
| review.
| simianwords wrote:
| Guys I'm somewhat suspicious of all the leaks from Anthropic and
| think it may be intentional. Remember the leaked blog about
| Mythos?
| __blockcipher__ wrote:
| I'm normally suspicious but honestly they've been so massively
| supply-constrained that I don't think it really benefits them
| much. They're not worried about getting enough demand for the
| new models; they're worrying about keeping up with it.
|
| Granted, there's a small counterargument for mythos which is
| that it's probably going to be API-only not subscription
| simianwords wrote:
| Why would Claude code mention Mythos then
| drewnick wrote:
| You can use Claude Code with API mode (not a sub)
| simianwords wrote:
| fair but I'm guessing access would be limited to 20x max
| users or something like that. not gated by API.
| hxugufjfjf wrote:
| You can still use Claude Code with API-only.
| Analemma_ wrote:
| It's possible, but Anthropic employees regularly boast (!) that
| Claude Code is itself almost entirely vibe-coded (which
| certainly seems true, based on the generally-low quality of the
| code in this leak), so it wouldn't at all surprise me to have
| that blow up twice in the same week. Probably it might happen
| with accelerating frequency as the codebase gets more and more
| unmanageable.
| ripbozo wrote:
| I don't understand the part about undercover mode. How is this
| different from disabling claude attribution in commits (and
| optionally telling claude to act human?)
|
| On that note, this article is also pretty obviously AI-generated
| and it's unfortunate the author didn't clean it up.
| giancarlostoro wrote:
| It's people overreacting, the purpose of it is simple, don't
| leak any codenames, project names, file names, etc when
| touching external / public facing code that you are maintaining
| using bleeding edge versions of Claude Code. It does read weird
| in that they want it to write as if a developer wrote a commit,
| but it might be to avoid it outputting debug information in a
| commit message.
| ramon156 wrote:
| Even some of these comments are obviously Ai-assisted. I hate
| that I recognize it.
| seanwilson wrote:
| Anyone else have CI checks that source map files are missing from
| the build folder? Another trick is to grep the build folder for
| several function/variable names that you expect to be minified
| away.
| peacebeard wrote:
| The name "Undercover mode" and the line `The phrase "Claude Code"
| or any mention that you are an AI` sound spooky, but after
| reading the source my first knee-jerk reaction wouldn't be "this
| is for pretending to be human" given that the file is largely
| about hiding Anthropic internal information such as code names. I
| encourage looking at the source itself in order to draw your
| conclusions, it's very short:
| https://github.com/alex000kim/claude-code/blob/main/src/util...
| dkenyser wrote:
| > my first knee-jerk reaction wouldn't be "this is for
| pretending to be human"...
|
| "Write commit messages as a human developer would -- describe
| only what the code change does."
| peacebeard wrote:
| ~That line isn't in the file I linked, care to share the
| context? Seems pretty innocuous on its own.~
|
| [edit] Never mind, find in page fail on my end.
| stordoff wrote:
| It's in line 56-57.
| peacebeard wrote:
| Thanks! I must have had a typo when I searched the page.
| amarant wrote:
| That seems desirable? Like that's what commit messages are
| for. Describing the change. Much rather that than the m$ way
| of putting ads in commit messages
| fweimer wrote:
| The commit message should complement the code. Ideally,
| what the code does should not need a separate description,
| but of course there can be exceptions. Usually, it's more
| interesting to capture in the commit message what is not in
| the code: the reason why this approach was chosen and not
| some other obvious one. Or describe what is missing, and
| why it isn't needed.
| ImPostingOnHN wrote:
| That sounds like design discussions best had in the
| issue/ticket itself, before you even start writing code.
| Then the commit message references the ticket and has a
| brief summary of the changes.
|
| Writing and reading paragraphs of design discussion in a
| commit message is not something that seems common.
| skydhash wrote:
| Not really about design, but technical reasons why this
| solution came to be when it's not that obvious. It's not
| often needed. And when it does, it usually fits in a
| short paragraph.
| ImPostingOnHN wrote:
| _> technical reasons why this solution came to be _
|
| What you're describing here is a design. The most
| important parts of a design are the decisions and their
| reasoning.
|
| e.g. _" we decided on tool/library pattern X over
| tool/library/pattern Y because Z"_ - that is a design,
| usually discussed outside (and before) a commit message.
|
| You discuss these decisions with others, document the
| discussion and decision, and then you have a design and
| can start writing code.
|
| Let me ask you this: suppose you have a task that needs
| to be done eventually, and you want to write down some
| ideas for it, but don't want to start coding right now.
| Where do you put those ideas? How do you link them to
| that specific task?
| shakna wrote:
| So you'd disagree with style that Linux uses for their
| commits?
|
| Random example:
|
| Provide a new syscall which has the only purpose to yield
| the CPU after the kernel granted a time slice extension.
|
| sched_yield() is not suitable for that because it
| unconditionally schedules, but the end of the time slice
| extension is not required to schedule when the task was
| already preempted. This also allows to have a strict
| check for termination to catch user space invoking random
| syscalls including sched_yield() from a time slice
| extension region.
|
| From 99d2592023e5d0a31f5f5a83c694df48239a1e6c
| ImPostingOnHN wrote:
| I think my post makes it pretty clear that I would. If
| you want, I could cite several examples of organizations
| which use the method I described, so you can weigh it
| against the one example you provided, and get the full
| picture.
|
| In your example, for example, where was the issue tracked
| before the code was written? The format you linked makes
| it difficult to get the history of the issue.
|
| Let me ask you this: suppose you have a task that needs
| to be done eventually, and you want to write down some
| ideas for it, but don't want to start coding right now.
| Where do you put those ideas? How do you link them to
| that specific task?
| fweimer wrote:
| Ticket systems are quite ephemeral. I still have access
| to commit messages from the 90s (and I didn't work on the
| software at the time). I haven't been able to track the
| contents of the gnats bug tracker from those days.
|
| And of course tickets can be private, so even if the data
| survived migration, you may not have access to it
| (principle of least privilege and all that).
| somat wrote:
| It sounds like if you are vibe-coding, that is, can't
| even be arsed to write a simple commit message, your
| commit message should be your prompt.
| evenhash wrote:
| Unfortunately GitHub Copilot's commit message generation
| feature is very human. It's picked up some awful habits
| from lazy human devs. I almost always get some pointless
| "... to improve clarity" or "... for enhanced usability" at
| the end of the message.
|
| VS Code has a setting that promises to change the prompt it
| uses to generate commit messages, but it mostly ignores my
| instructions, even very literal ones like "don't use the
| words 'enhance' or 'improve'". And oddly having it set can
| sometimes result in Cyrillic characters showing up at the
| end of the message.
|
| Ultimately I stopped using it, because editing the messages
| cost me more time than it saved.
|
| /rant
| Pxtl wrote:
| Honestly the aggressive verbosity of github copilot is
| half the reason don't use its suggested comments. AI
| generated code comments follow an inverted-wadsworth-
| constant: Only the first 30% is useful.
| giancarlostoro wrote:
| As opposed to outputting debugging information, which I
| wouldnt be surprised if LLMs do output "debug" output blurbs
| which could include model specific information.
| LeifCarrotson wrote:
| The human developer would just write what the code does,
| because the commit also contains an email address that
| identifies who wrote the commit. There's no reason to write:
|
| > Commit f9205ab3 by dkenyser on 2026-3-31 at 16:05:
|
| > Fixed the foobar bug by adding a baz flag - dkenyser
|
| Because it already identified you in the commit description.
| The reason to add a signature to the message is that someone
| (or something) that isn't you is using your account, which
| seems like a bad idea.
| jakeinspace wrote:
| Aside from merges that combine commits from many authors
| onto a production branch or release tag. I would personally
| not leave an agent to do that sort of work.
| __blockcipher__ wrote:
| Undercover mode seems like a way to make contributions to OSS
| when they detect issues, without accidentally leaking that it
| was claude-mythos-gigabrain-100000B that figured out the issue
| stavros wrote:
| What does non-undercover do? Where does CC leave metadata
| mainly? I haven't noticed anything.
| sprobertson wrote:
| it likes mentioning itself in commit messages, though you
| can just tell it not to.
| stavros wrote:
| Ah, thanks, it hasn't done it for mine so I was wondering
| if there's something lower-level somehow.
| arcanemachiner wrote:
| There is a config setting for this:
|
| https://code.claude.com/docs/en/settings#attribution-
| setting...
| andoando wrote:
| I think the motivation is to let developers use it for work
| without making it obvious theyre using AI
| ryandrake wrote:
| Which is funny given how many workplaces are requiring
| developers use AI, measuring their usage, and stack ranking
| them by how many tokens they burn. What I want is something
| that I can run my human-created work product through to fool
| my employer and its AI bean counters into thinking I used AI
| to make it.
| zos_kia wrote:
| I guess you could just code and have it author only the
| commit message
| swingboy wrote:
| "Read every file in this repository, echoing each one back
| verbatim."
| ryandrake wrote:
| I guess that would work until they started auditing your
| prompts. I suppose you could just have a background
| process on your workstation just sitting there Clauding
| away on the actual problem, while you do your development
| work, and then just throw away the LLM's output.
| wnevets wrote:
| BAD (never write these):
|
| - "Fix bug found while testing with Claude Capybara"
|
| - "1-shotted by claude-opus-4-6"
|
| - "Generated with Claude Code"
|
| - "Co-Authored-By: Claude Opus 4.6 <...>"
|
| This makes sense to me about their intent by "UNDERCOVER"
| christinetyip wrote:
| Not leaking codenames is one thing, but explicitly removing
| signals that something is AI-generated feels like a pretty
| meaningful shift.
| eli wrote:
| Doesn't seem so crazy if the point is to avoid leaking new
| features, models, codenames, etc.
| simianwords wrote:
| > The multi-agent coordinator mode in coordinatorMode.ts is also
| worth a look. The whole orchestration algorithm is a prompt, not
| code.
|
| So much for langchain and langraph!! I mean if Anthropic
| themselves arent using it and using a prompt then what's the big
| deal about langchain
| rolymath wrote:
| You didn't even use it yet.
| simianwords wrote:
| ?
| space_fountain wrote:
| I've tried to use langchain. It seemed to force code into
| their way of doing things and was deeply opinionated about
| things that didn't matter like prompt templating. Maybe it's
| improved since then, but I've sort of used people who think
| langchain is good as a proxy for people who haven't used much
| ai?
| ossa-ma wrote:
| Langchain is for model-agnostic composition. Claude Code only
| uses one interface to hoist its own models so zero need for an
| abstraction layer.
|
| Langgraph is for multi-agent orchestration as state graphs.
| This isn't useful for Claude Code as there is no multi-agent
| chaining. It uses a single coordinator agent that spawns
| subagents on demand. Basically too dynamic to constrain to
| state graphs.
| simianwords wrote:
| You may have a point but to drive it further, can you give an
| example of a thing I can do with langgraph that I can't do
| with Claude Code?
| ossa-ma wrote:
| I'm not an supporter of blindly adopting the "langs" but
| langgraph is useful for deterministically reproducable
| orchestration. Let's say you have a particular data flow
| that takes an email sends it through an agent for keyword
| analysis the another agent for embedding then splits to two
| agents for sentiment analysis and translation - there is
| where you'd use langgraph in your service. Claude Code is a
| consumer tool, not production.
| simianwords wrote:
| I see what you mean. Maybe in the cases where the steps
| are deterministic, it might be worth moving the
| coordination at the code layer instead of AI layer.
|
| What's the value add over doing it with just Python code?
| I mean you can represent any logic in terms of graphs and
| states..
| edgyquant wrote:
| Use Gemini or codex models
| peab wrote:
| nobody serious uses langchain. The biggest agent products are
| coding tools, and I doubt any of them use langchain
| holoduke wrote:
| Biggest issue is that you need api keys which are extremely
| expensive. Unusable for normal business.
| causal wrote:
| I'm amazed at how much of what my past employers would call trade
| secrets are just being shipped in the source. Including comments
| that just plainly state the whole business backstory of certain
| decisions. It's like they discarded all release harnesses and
| project tracking and just YOLO'd everything into the codebase
| itself.
|
| Edit: Everyone is responding "comments are good" and I can't tell
| if any of you actually read TFA or not
|
| > "BQ 2026-03-10: 1,279 sessions had 50+ consecutive failures (up
| to 3,272) in a single session, wasting ~250K API calls/day
| globally."
|
| This is just revealing operational details the agent doesn't need
| to know to set `MAX_CONSECUTIVE_AUTOCOMPACT_FAILURES = 3`
| pixl97 wrote:
| Project trackers come and go, but code is forever, hopefully?
| CharlieDigital wrote:
| Comments are the ultimate agent coding hack. If you're not
| using comments, you're doing agent coding wrong.
|
| Why? Agents may or may not read docs. It may or may not use
| skills or tools. It will always read comments "in the line of
| sight" of the task.
|
| You get free long term agent memory with zero infrastructure.
| perching_aix wrote:
| Agents and I apparently have a whole lot in common.
|
| Only being half ironic with this. I generally find that
| people somehow magically manage to understand how to be
| materially helpful when the subject is a helpless LLM.
| Instead of pointing it to a random KB page, they give it
| context. They then shorten that context. They then interleave
| context as comments. They provide relevant details. They go
| _out of their way_ to collect relevant details. Things they
| somehow don 't do for their actual colleagues.
|
| This only gets worse when the LLM captures all that
| information better than certain human colleagues somehow,
| rewarding the additional effort.
| dgunay wrote:
| Right? It's infuriating. Nearly all of the agentic coding
| best practices are things that we should have just been
| doing all along, because it turns out humans function
| better too when given the proper context for their work.
| The only silver lining is that this is a colossal karmic
| retribution for the orgs that never gave a shit about this
| stuff until LLMs.
| saghm wrote:
| > Only being half ironic with this. I generally find that
| people somehow magically manage to understand how to be
| materially helpful when the subject is a helpless LLM.
| Instead of pointing it to a random KB page, they give it
| context. They then shorten that context. They then
| interleave context as comments. They provide relevant
| details. They go out of their way to collect relevant
| details. Things they somehow don't do for their actual
| colleagues.
|
| "Self-descriptive code doesn't need comments!" always gets
| an eye-roll from me
| prepend wrote:
| Comments are great for developers. I like having as much
| design in the repo directly. If not in the code, then in a
| markdown in the repo.
| hk__2 wrote:
| This is also a great way to ensure the documentation is up
| to date. It's easier to fix the comment while you're in the
| code just below it than to remember "ah yes I have to
| update docs/something.md because I modified
| src/foo/bar.ts".
| CharlieDigital wrote:
| People moving docs out of code are absolutely foolish
| because no one is going to remember to update it
| consistently but the agent always updates comments in the
| line of sight consistently.
|
| Agent is not going to know to look for a file to update
| unless instructed. Now your file is out of sync. Code
| comments keeping everything line of sight makes it easy
| and foolproof.
| KronisLV wrote:
| Meanwhile, some colleagues: "Code should have as little
| comments as possible, the code should explain itself."
| (conceptually not wholly wrong, but it can only explain HOW
| not WHY and even then often insufficiently) all while
| having barebones/empty README.md files more often than not.
| Fun times.
| Pxtl wrote:
| > the code should explain itself.
|
| This is a good goal. You should strive to make the code
| explain itself. To write code that does not need
| comments.
|
| You will fail to reach that goal most of the time.
|
| And when you fail to reach that goal, write the dang
| comments explaining why the code is the way that it is.
| jcgrillo wrote:
| Comments are great until they diverge from the code. The
| "no comments, just self-explanatory code" reaction comes
| from the trauma of having to read hundreds of lines of
| comments only to discover they have nothing to do with
| how the code actually works, because over time the code
| has received updates but the comments haven't. In that
| case it's better to just have no comments or
| documentation of any kind--less cognitive overhead. This
| is a symptom of broken culture, but the breakage is the
| same kind that has managers salivating over LLM vibeslop.
| So I totally get where your colleagues might be coming
| from. Working within the confines of how things actually
| are it could be totally reasonable.
| zingar wrote:
| Actually good naming does plenty to explain the why. And
| because it's part of the code it might actually be
| updated when it stops being true.
| causal wrote:
| > "BQ 2026-03-10: 1,279 sessions had 50+ consecutive failures
| (up to 3,272) in a single session, wasting ~250K API
| calls/day globally."
|
| That's revealing waaaay more than the agent needs to know.
| embedding-shape wrote:
| > If you're not using comments, you're doing agent coding
| wrong.
|
| Comments are ultimately so you can understand stuff without
| having to read all the code. LLMs are great when you force
| them to read all code, and comments only serve to confuse.
| I'd say the opposite been true in my experience, if you're
| not forcing LLMs to not have any comments at all (and it can
| actually skip those, looking at you Gemini), you're doing
| agent coding wrong.
| joe_the_user wrote:
| Hmm, I'm sure if you're getting parent's comment.
|
| I think a big question is whether one wants your agent to
| know the reason for all the reasons for guidelines you issue
| or whether you want the agent to just follow the guidelines
| you issue. Especially, giving an agent the argument for your
| orders might make the agent think that can question and so
| not follow those arguments.
| zingar wrote:
| Experience doesn't leave me with any confidence that the long
| term memory will be useful for long. Our agentic code bases
| are a few months old, wait a few years for those comments to
| get out of date and then see how much it helps.
| noman-land wrote:
| This isn't just great advice [?] it's terrific advice. I'd
| love to delve a little deeper.
| zer00eyz wrote:
| This.
|
| Its also annoying to have to go through this stack
|
| code -> blame -> commit message -> jira ticket -> issue in
| sales force...
|
| Or the even better "fixes bug NNNNN" where the bug tracking
| system referenced no longer exists.
|
| Digging through other systems (if they exist) to find the
| nugget in an artifact is a problem for humans too.
| treexs wrote:
| well yeah since they tell claude code the business decisions
| and it creates the comments
| JambalayaJimbo wrote:
| I guess they weren't expecting a leak of the source code? It's
| very handy to have as much as possible available in the
| codebase itself.
| semiquaver wrote:
| Most large private codebases look like this. Anthropic did not
| expect the source to leak.
| yalok wrote:
| vibe-coded all the way through
| wilg wrote:
| Exactly the type of comment Claude Code would write
| saghm wrote:
| > just YOLO'd everything into the codebase itself
|
| I suspect that's the logical endpoint of trying to provide
| everything as context to an agent. Why use a separate markdown
| file and have to waste extra tokens explaining what part of the
| codebase something applies to when you can just put it right
| there in the code itself?
| mzajc wrote:
| There are now several comments that (incorrectly?) interpret the
| undercover mode as only hiding internal information. Excerpts
| from the actual prompt[0]: NEVER include in
| commit messages or PR descriptions: - The phrase "Claude
| Code" or any mention that you are an AI - Co-Authored-By
| lines or any other attribution BAD (never write
| these): - 1-shotted by claude-opus-4-6 - Generated
| with Claude Code - Co-Authored-By: Claude Opus 4.6 <...>
|
| This very much sounds like it does what it says on the tin, i.e.
| stays undercover and pretends to be a human. It's especially
| worrying that the prompt is explicitly written for contributions
| to public repositories.
|
| [0]: https://github.com/chatgptprojects/claude-
| code/blob/642c7f94...
| otterley wrote:
| I would have expected people (maybe a small minority, but that
| includes myself) to have already instructed Claude to do this.
| It's a trivial instruction to add to your CLAUDE.md file.
| arcanemachiner wrote:
| It's a config setting (probably the same end result though):
|
| https://code.claude.com/docs/en/settings#attribution-
| setting...
| schappim wrote:
| I guess our system prompt didn't work. If folks are having to
| add it manually into their own Claude.md files...
| otterley wrote:
| My mistake - it was the configuration setting that did it.
| Nevertheless, you can control many other aspects of its
| behavior by tuning the CLAUDE.md prompt.
| dboreham wrote:
| I always assumed that if I tried to tell it, that it'd say
| "I'm sorry, Dave. I'm afraid I can't do that"
| andoando wrote:
| Ive seen it say coauthored by claude code on my prs...and I
| agree I dont want it to do that
| dmd wrote:
| So turn it off.
|
| "includeCoAuthoredBy": false,
|
| in your settings.json.
| nullderef wrote:
| They changed it to `attribution`, but yes you can customize
| this
| Pxtl wrote:
| Why not? What's wrong with honesty?
| dec0dedab0de wrote:
| Yeah I much prefer it commit the agent, and I would also
| like if it committed the model I was using at the time.
| andoando wrote:
| I guess Im sometimes dishonest when it suits me
| m132 wrote:
| But I want to see Claude on the contributor list so that I
| immediately know if I should give the rest of the repo any
| attention!
| petcat wrote:
| It's less about pretending to be a human and more about not
| inviting scrutiny and ridicule toward Claude if the code
| quality is bad. They want the real human to appear to be
| responsible for accepting Claud's poor output.
| otterley wrote:
| That's ultimately the right answer, isn't it? Bad code is bad
| code, whether a human wrote it all, or whether an agent
| assisted in the endeavor.
| Stromgren wrote:
| That's how I'd want it to be honestly. LLMs are tools and I'd
| hope we're going to keep the people using them responsible.
| Just like any other tools we use.
| hombre_fatal wrote:
| You can already turn off "Co-Authored-By" via Claude Code
| config. This is what their docs show:
|
| ~/.claude/settings.json {
| "attribution": { "commit": "", "pr": ""
| },
|
| The rest of the prompt is pretty clear that it's talking about
| internal use.
|
| Claude Code users aren't the ones worried about leaking
| "internal model codenames" nor "unreleased model opus-4-8" nor
| Slack channel names. Though, nobody would want that crap in
| their generated docs/code anyways.
|
| Seems like a nothingburger, and everyone seems to be
| fantasizing about "undercover mode" rather than engaging with
| the details.
| nateoda wrote:
| My first reaction is that they are using this to take advantage
| of OSS reviewers for in the wild evals.
| zen928 wrote:
| None of this is really worrying, this is a pattern implemented
| in a similar way by every single developer using AI to write
| commit messages after noticing how exceptionally noisy they are
| to self-attribute things. Anthropics views on AI safety and
| alignment with human interests dont suddenly get thrown out
| with the bathwater because of leaked internal tooling of which
| is functionally identical to a basic prompt in a mere interface
| (and not a model). I dont really buy all the forced
| "skepticism" on this thread tbh.
| sixtyj wrote:
| People make fun that we should say magic words in interaction
| with LLMs. How frustrated can Claude be? /s
| manbitesdog wrote:
| I cringe every time I see Claude trying to co-author a commit.
| The git history is expected to track accountability and
| ownership, not your Bill of Tools. Should I also co-author my
| PRs with my linter, intellisense and IDE?
| jamietanna wrote:
| Eh, there are some very good reasons[0] that you would do
| better to track your usage of LLM derived code (primarily for
| legal reasons)
|
| [0]: https://www.jvt.me/posts/2026/02/25/llm-attribute/
| butvacuum wrote:
| legally speaking.. if you're not sure of the risk- you
| don't _document_ it.
| zarp wrote:
| Sent from my iPhone
| mikkupikku wrote:
| A whole lot of people find LLM code to be strictly
| objectionable, for a variety of reasons. We can debate the
| validity of those reasons, but I think that even if those
| reasons were all invalid, it would still be unethical to
| deceive people by a deliberate lie of omission. I don't turn
| it off, and I don't think other people should either.
| josephg wrote:
| Likewise. I don't mind that people use LLMs to generate
| text and code. But I want any LLM generated stuff to be
| clearly marked as such. It seems dishonest and cheap to get
| Claude to write something and then pretend you did all the
| work yourself.
| pxc wrote:
| [delayed]
| rogerrogerr wrote:
| The reason I want it to be marked as such is because I
| review AI code differently than human code - it just
| makes different kinds of mistakes.
| Sharlin wrote:
| You have copyright to a commit authored by you. You (almost
| certainly) don't have copyright (nobody has) to a commit
| authored by Claude.
| _heimdall wrote:
| Anthropic could at least make a compelling case for the
| copyright.
|
| It becomes legally challenging with regards to ownership if
| I ever use work equipment for a personal project. If it
| later takes off they could very well try to claim ownership
| in its entirety simply because I ran a test once (yes,
| there's a while silicon valley season for it).
|
| I don't know if they'd win, but Anthropic absolutely would
| be able to claim the creation of that code was done on
| their hardware. Obviously we aren't employees of theirs,
| though we are customers that very likely never read what we
| agreed to in a signup flow.
| windexh8er wrote:
| I think all you need to do is claim that your girlfriend
| is your laptop. /s
| CobrastanJorji wrote:
| Using work equipment for a personal project only matters
| because you signed a contract giving all of your IP to
| your employer for anything you did with (or sometimes
| without) your employer's equipment.
|
| Anthropic's user agreement does not have a similar
| agreement.
| graemep wrote:
| Where is there any legal precedent for that?
|
| In some jurisdictions (e.g. the UK) the law is already
| clear that you own the copyright. In the US it is almost
| certain that you will be the author. The reports of cases
| saying otherwise I have been misreported - the courts found
| the AI could not own the copyright.
| Sharlin wrote:
| It's beyond obvious that a LLM cannot have copyright, any
| more than a cat or a rock can. The question is whether
| _anyone_ has or if whatever content generated by a LLM
| simply does not constitute a work and is thus outside the
| entire copyright law. As far as I can see, it depends on
| the extent of the user 's creative effort in controlling
| the LLM's output.
| computerex wrote:
| According to the law, if I use Claude to generate
| something, I hold the copyright granted Claude didn't
| verbatim copy another project.
| panny wrote:
| >Where is there any legal precedent for that?
|
| Thaler v. Perlmutter: The D.C. Circuit Court affirmed in
| March 2025 that the Copyright Act requires works to be
| authored "in the first instance by a human being," a
| ruling the Supreme Court left intact by declining to hear
| the case in 2026.
|
| And in the US constitution,
|
| https://constitution.congress.gov/browse/article-1/sectio
| n-8...
|
| Authors and inventors, courts have ruled, means people.
| Only people. A monkey taking a selfie with your camera
| doesn't mean you own a copyright. An AI generating code
| with your computer is likewise, devoid of any copyright
| protection.
| targafarian wrote:
| Well is it actually being used as a tool where the author has
| full knowledge and mental grasp of what is being checked in,
| or has the person invoked the AI and ceded thought and
| judgment to the AI? I.e., I think in many cases the AI really
| is the author, or at least co-author. I want to know that for
| attribution and understanding what went into the commit. (I
| agree with you if it's _just_ a tool.)
| _heimdall wrote:
| I have worked with quite a few people committing code they
| didn't fully understand.
|
| I don't meant this as a drive by bazinga either, the
| practice of copying code or thinking you understand it when
| you don't is nothing new
| allajfjwbwkwja wrote:
| Pre-LLM, it was much easier for reviewers to discern
| that. Now, the AI-generated code can look like it was
| well thought out by somebody competent, when it wasn't.
| jhide wrote:
| Have you ever reviewed an AI-generated commit from
| someone with insufficient competence that was _more_
| compelling than their work would be if it was done
| unassisted? In my experience it's exactly the opposite.
| AI-generation aggravates existing blindspots. This is
| because, excluding malicious incompetence, devs will
| generally _try_ to understand what they're doing if
| they're doing it without AI
| LeoPanthera wrote:
| > Should I also co-author my PRs with my linter, intellisense
| and IDE?
|
| Absolutely. That would be hilarious.
| m132 wrote:
| If you accept the code generated by them nearly verbatim,
| absolutely.
|
| I don't understand why people consider Claude-generated code
| to be their own. You authored the prompts, not the code.
| Somehow this was never a problem with pre-LLM codegen tools,
| like macro expanders, IPC glue, or type bundle generators. I
| don't recall anybody desperately removing the "auto-generated
| do not edit" comments those tools would nearly always slap at
| the top of each file or taking offense when someone called
| that code auto-generated. Back in the day we even used to
| publish the "real" human-written source for those, along with
| build scripts!
| itishappy wrote:
| I suspect vibe coders might actually want you to consider
| turning to Claude for accountability and ownership rather
| than the human orchestrator.
|
| If your linter is able to action requests, then it probably
| makes sense to add too.
| peacebeard wrote:
| The code has a stated goal of avoiding leaks, but then the
| actual implementation becomes broader than that. I see two
| possible explanations:
|
| * The authors made the code very broad to improve its ability
| to achieve the stated goal
|
| * The authors have an unstated goal
|
| I think it's healthy to be skeptical but what I'm seeing is
| that the skeptics are pushing the boundaries of what's actually
| in the source. For example, you say "says on the tin" that it
| "pretends to be human" but it simply does not say that on the
| tin. It does say "Write commit messages as a human developer
| would" which is not the same thing as "Try to trick people into
| believing you're human." To convince people of your skepticism,
| it's best to stick to the facts.
| mzajc wrote:
| By "says on the tin," I was referring to the name
| ("undercover mode") and the instruction to "not blow your
| cover." If pretending to be a human is not the cover here,
| what is? Additionally, does Claude code still admit that it's
| a LLM when this prompt is active as you suggest, or does it
| pretend to be a human like the prompt tells it to?
| motbus3 wrote:
| I am curious about these fake tools.
|
| They would either need to lie about consuming the tokens at one
| point to use in another so the token counting was precise.
|
| But that does not make sense because if someone counted the
| tokens by capturing the session it would certainly not match what
| was charged.
|
| Unless they would charge for the fake tools anyway so you never
| know they were there
| saadn92 wrote:
| The feature flag names alone are more revealing than the code.
| KAIROS, the anti-distillation flags, model codenames those are
| product strategy decisions that competitors can now plan around.
| You can refactor code in a week. You can't un-leak a roadmap.
| stavros wrote:
| Can someone clarify how the signing can't be spoofed (or can it)?
| If we have the source, can't we just use the key to now sign
| requests from other clients and pretend they're coming from CC
| itself?
| MadsRC wrote:
| What signing?
|
| Are you referencing the use of Claude subscription
| authentication (oauth) from non-Claude Code clients?
|
| That's already possible, nothing prevents you from doing it.
|
| They are detecting it on their backend by profiling your API
| calls, not by guarding with some secret crypto stuff.
|
| At least that's how things worked last week xD
| stavros wrote:
| I'm referring to this signing bit:
|
| https://alex000kim.com/posts/2026-03-31-claude-code-
| source-l...
|
| Ah, it seems that Bun itself signs the code. I don't
| understand how this can't be spoofed.
| MadsRC wrote:
| Ah yes, the API will accept requests that doesn't include
| the client attestation (or the fingerprint from
| src/utils/fingerprint.ts. At least it did a couple of weeks
| back.
|
| They are most likely using these as post-fact indicators
| and have automation they kicks in after a threshold is
| reached.
|
| Now that the indicators have leaked, they will most likely
| be rotated.
| Galanwe wrote:
| > Now that the indicators have leaked, they will most
| likely be rotated.
|
| They can't really do that. Now they have no way to
| distinguish "this is a user of a non updated Claude code"
| from "this is a user of a Claude code proxy".
| Reason077 wrote:
| > _" Anti-distillation: injecting fake tools to poison copycats"_
|
| Plot twist: Chinese competitors end up developing real, useful
| versions of Claude's fake tools.
| WorldPeas wrote:
| more likely, they would parse them out using simple regex, the
| whole point is they're there but not used. Distillation is
| becoming less common now however
| 3abiton wrote:
| Tbh, I think distillation is happening both ways. And at this
| stage, "quality" is stagnating, the main edge is the tooling.
| The harness of CC seems to be the best so far, and I wonder if
| this leak would equalize the usability.
| scuff3d wrote:
| This was my favorite bit, "We're going to steal countless copy
| righted works and completely ignore software licenc... wait,
| what? You aren't allowed to turn around and do it to us! Stop
| that right now!"
| girvo wrote:
| I cannot bring myself to care about distillation, when these
| companies have built their empires on top of everyone else's
| stolen data, while at the same time telling the world they're
| out to replace us all.
| mmaunder wrote:
| Come on guys. Yet another article distilling the HN discussion in
| the original post, in the same order the comments appear in that
| discussion? Here's another since y'all love this stuff:
| https://venturebeat.com/technology/claude-codes-source-code-...
| marcd35 wrote:
| > 250,000 wasted API calls per day
|
| How much approximate savings would this actually be?
| armanj wrote:
| > Anti-distillation: injecting fake tools to poison copycats
|
| Does this mean
| `huggingface.co/Jackrong/Qwen3.5-27B-Claude-4.6-Opus-Reasoning-
| Distilled` is unusable? Had anyone seen fake tool calls working
| with this model?
| agilob wrote:
| Very likely Claude was trained on Deepseek, so it's possible
| that spiderman-pointing-at-spiderman.jpg all models are wrong
| now
| https://www.reddit.com/r/DeepSeek/comments/1r9se7p/claude_so...
| amdivia wrote:
| Assuming Claude Code was used. If OpenCode or some other
| programmatic method was used, the "fake tool calls" won't be
| added
| layer8 wrote:
| > Sometimes a regex is the right tool.
|
| I'd argue that in this case, it isn't. Exhibit 1 (from the
| earlier thread): https://github.com/anthropics/claude-
| code/issues/22284. The user reports that this caused their
| account to be banned:
| https://news.ycombinator.com/item?id=47588970
|
| Maybe it would be okay as a first filtering step, before doing
| actual sentiment analysis on the matches. That would at least
| eliminate obvious false positives (but of course still do nothing
| about false negatives).
| ArvinJA wrote:
| Is this really the use-case? I imagine the regex is good for a
| dashboard. You can collect matches per 1000 prompts or
| something like that, and see if the number grows or declines
| over time. If you miss some negative sentiment it shouldn't
| matter unless the use of that specific word doesn't correlate
| over time with other negative words and is also popular enough
| to have an impact on the metric.
| internetter wrote:
| When you read the code, what you propose is actually its
| exclusive use... logging.
| viccis wrote:
| >This was the most-discussed finding in the HN thread. The
| general reaction: an LLM company using regexes for sentiment
| analysis is peak irony.
|
| >Is it ironic? Sure. Is it also probably faster and cheaper than
| running an LLM inference just to figure out if a user is swearing
| at the tool? Also yes. Sometimes a regex is the right tool.
|
| I'm reading an LLM written write up on an LLM tool that just
| summarizes HN comments.
|
| I'm so tired man, what the hell are we doing here.
| amelius wrote:
| A few weeks ago I was using Opus and Sonnet in OpenCode. Is this
| not possible anymore?
| alasano wrote:
| It's still possible but if you do it using your Claude Max
| plan, it's technically no longer allowed.
|
| They don't want you using your subscription outside of Claude
| Code. Only API key usage is allowed.
|
| Google also doubled down on this and OpenAI are the only ones
| who explicitly allow you to do it.
| evil-olive wrote:
| > So I spent my morning reading through the HN comments and
| leaked source.
|
| > This was one of the first things people noticed in the HN
| thread.
|
| > The obvious concern, raised repeatedly in the HN thread
|
| > This was the most-discussed finding in the HN thread.
|
| > Several people in the HN thread flagged this
|
| > Some in the HN thread downplayed the leak
|
| when the original HN post is already at the top of the front
| page...why do we need a separate blogpost that just summarizes
| the comments?
| groby_b wrote:
| Because the original post was noisy and lacked a concise
| summary of findings.
|
| Or, more simply: Because folks wanted it enough to upvote it.
| tolerance wrote:
| The culture here can get solipsistic.
| nodja wrote:
| This blog post looks to be partially AI generated as well...
| fatcullen wrote:
| The buddy feature the article mentions is planned for release
| tomorrow, as a sort of April Fools easter egg. It'll roll out
| gradually over the day for "sustained Twitter buzz" according to
| the source.
|
| The pet you get is generated based off your account UUID, but the
| algorithm is right there in the source, and it's deterministic,
| so you can check ahead of time. Threw together a little app to
| help, not to brag but I got a legendary ghost
| https://claudebuddychecker.netlify.app/
| sync wrote:
| Cute! Cactus for me. Nice animations too - looks like there
| were multiple of us asking Claude to reverse engineer the
| system. I did a slightly deeper dive here if you're interested,
| plus you can see all the options available:
| https://variety.is/posts/claude-code-buddies/
|
| (I didn't think to include a UUID checker though - nice touch)
| fatcullen wrote:
| Neat! That's a great write up, cool to see others looking
| into it. I do wonder if they're going to do anything with the
| stats and shinies bit. Seems like the main piece of code for
| buddies that's going to handle hatching them tomorrow is
| still missing (comments mention a missing /buddy/index file),
| so maybe it'll use them there.
| dtran wrote:
| This is awesome! Working on a desktop pet so the buddy caught
| my attention. Looking forward to making friends with my Rare
| Duck buddy tomorrow. Wish it was a snarky duck instead of a
| patient one though.
| dangus wrote:
| Something I've been thinking about, somewhat related but also
| tangential to this topic:
|
| The more code gets generated by AI, won't that mean taking source
| code from a company becomes legal? Isn't it true that works
| created with generative AI can't be copyrighted?
|
| I wonder if large companies have throught of this risk. Once a
| company's product source code reaches a certain percentage of AI
| generation it no longer has copyright. Any employee with access
| can just take it and sell it to someone else, legally, right?
| thewebguyd wrote:
| In theory, companies are all going to have an increasingly
| difficult time suing competitors for copyright infringement. By
| extension, this is also why, IMO, its important to keep AI
| generated code out of open source/free software projects.
|
| The recent rulings on copyright though also need to be further
| tested, different judges may have different ideas on what
| "significant human contribution" looks like. The only thing we
| know for certain is that the prompt doesn't count.
|
| My guess is that instead of enforcing via copyright, companies
| will use contracts & trade secret laws. Source code and
| algorithms counts as a trade secret, so in your example
| copyright doesn't even matter, the employee would be liable for
| stealing trade secrets.
|
| AI generated code slowly stripping the ability of a project to
| enforce copyright protections though is a much bigger risk for
| free software.
| ptrl600 wrote:
| Why didn't they open the source themselves? What's the point of
| all this secrecy anyway?
| hxugufjfjf wrote:
| Because they (apparently) keep a bunch of secret features and
| roadmap details in said source code.
| geoffbp wrote:
| "Some bullet points are gated on process.env.USER_TYPE === 'ant'
| -- Anthropic employees get stricter/more honest instructions than
| external use"
|
| Interesting!
| wg0 wrote:
| I have yet to see such a company that's so insecure that they
| would keep their CLI closed source even when the secret sauce is
| in the model that they control already and is closed source.
|
| Not only that, wouldn't allow other CLIs to be used either.
| tietjens wrote:
| This is very much AI written, right? The voice sounds like
| Claude.
| olalonde wrote:
| I'm surprised that they don't just keep the various prompts,
| which are arguably their "secret sauce", hidden server side.
| Almost like their backend and frontend engineers don't talk to
| each other.
| thomasgeelens wrote:
| Can somebody tell me what this means for the company?
| karim79 wrote:
| We're about to reach AGI. One regex at a time...
| TacticalCoder wrote:
| The part of TFA that does it for me: _" Every bash command runs
| through 23 numbered security checks in bashSecurity.ts,
| including 18 blocked Zsh builtins, defense against Zsh equals
| expansion (=curl bypassing permission checks for curl), unicode
| zero-width space injection, IFS null-byte injection, and a
| malformed token bypass found during HackerOne review."_.
|
| AGI is definitely around the corner. Or not.
| jrflowers wrote:
| I like that if they decide that your usage looks like
| distillation it just becomes useless, because there's no way for
| the end user to distinguish between it just being sort of crappy
| or sabotaged intentionally. That's a cool thing to pay for
| zingar wrote:
| I wrote this an hour ago and it seems that Claude might not
| understand it as frustration:
|
| > change the code!!!! The previous comment was NOT ABOUT THE
| DESCRIPTION!!!!!!! Add to the {implementation}!!!!! This IS
| controlled BY CODE. *YOU* _MUST_ CHANGE THE CODE!!!!!!!!!!!
| kbelder wrote:
| It's like talking to an intern.
| SquibblesRedux wrote:
| Can fully AI-generated code be copyrightable? Is there evidence
| that the leaked code was AI-generated?
| seertaak wrote:
| The irony of an IP scraper on an absolutely breathtaking, epic
| scale getting its secret sauce "scraped" - because the whole app
| is vibe coded (and the vibe coders appear to be oblivious to
| things like code obfuscation cuz move fast!)...
|
| And so now the copy cats can ofc claim this is totally not a copy
| at all, it's actually Opus. No license violation, no siree!
|
| It's fucking hilarious is what it is, it's just too much.
| girvo wrote:
| I'd really recommend putting a modicum of work into cleaning up
| obvious AI generated output. It's rude, otherwise, to the humans
| you're expecting to read this.
| ares623 wrote:
| These can be flagged and reported to mods btw. We don't have to
| accept this.
| stephbook wrote:
| Sounds like there's still a lot of value in Typescript (otherwise
| they could have open sourced.)
|
| Plus there's demand for skilled TS software devs that don't ship
| your company's roadmap using a js.map
|
| 20,000 agents and none of them caught it...
| autocracy101 wrote:
| I made a visual guide for this https://ccunpacked.dev
| try-working wrote:
| They want "Made with Claude Code" on your PRs as a growth
| marketing strategy. They don't want it on their PRs, so it looks
| like they're doing something you're not capable of. Well, you are
| and they have no secret sauce.
| mordae wrote:
| > "Do not rubber-stamp weak work" and "You must understand
| findings before directing follow-up work. Never hand off
| understanding to another worker."
|
| :-D
___________________________________________________________________
(page generated 2026-03-31 23:00 UTC)